Skip to content

feat(sync): scheduled upstream-sync that opens PRs per source repo - #8

Merged
DeepDiver1975 merged 1 commit into
mainfrom
feat/upstream-sync-prs
Jun 17, 2026
Merged

feat(sync): scheduled upstream-sync that opens PRs per source repo#8
DeepDiver1975 merged 1 commit into
mainfrom
feat/upstream-sync-prs

Conversation

@DeepDiver1975

Copy link
Copy Markdown
Member

What

Adds a scheduled GitHub Actions workflow that keeps the monorepo current with the
legacy owncloud/docs-* repos, where active documentation contributions still
land. Each run mirrors every mapped upstream branch's modules/ into its monorepo
folder and opens one pull request per source repo with the diff.

Why

The monorepo was seeded by a one-time plain copy and had no mechanism to stay
current — upstream edits never reached it. This closes that gap with cloud-only,
token-free automation.

How

  • sync/manifest.yml — single source of truth for the branch→folder mapping
    (e.g. each repo's master → its in-dev/prerelease folder). Adding a version =
    one entry here.
  • sync/sync-repo.shyq-driven mirror of the sync_paths allowlist
    (modules). Mirror/replace: upstream wins, stale files removed. The
    monorepo-managed antora.yml is never touched.
  • .github/workflows/sync-upstream.yml — daily (03:00 UTC) +
    workflow_dispatch; a matrix over the manifest runs each repo in its own job
    and opens/updates sync/<repo> via peter-evans/create-pull-request.

Stateless and self-correcting — no SHA baseline, no drift.

Verification done

  • bash -n + YAML lint pass.
  • Live dry-run of sync-repo.sh docs-webui: produced a real upstream diff,
    re-run was idempotent, and content/webui/antora.yml was confirmed unchanged.
  • This PR adds tooling only — no content change, build unaffected.

Before enabling the schedule

Confirm the master→dev-folder rows and the ocis 8.0 vs master choice in
sync/manifest.yml match maintainer intent.

🤖 Generated with Claude Code

Active documentation contributions still land in the legacy owncloud/docs-*
repos. This adds a daily GitHub Actions workflow that mirrors each upstream
branch's modules/ into the mapped monorepo folder and opens one pull request
per source repo with the diff.

- sync/manifest.yml: branch->folder mapping (single source of truth)
- sync/sync-repo.sh: yq-driven mirror of sync_paths, preserves antora.yml
- .github/workflows/sync-upstream.yml: schedule + matrix + create-pull-request

Mirror mode is stateless and self-correcting; antora.yml and other
monorepo-managed files are never overwritten.

Signed-off-by: Thomas Müller <1005065+DeepDiver1975@users.noreply.github.com>
@DeepDiver1975
DeepDiver1975 merged commit 64001f8 into main Jun 17, 2026
2 checks passed
@DeepDiver1975
DeepDiver1975 deleted the feat/upstream-sync-prs branch June 17, 2026 12:01
DeepDiver1975 added a commit that referenced this pull request Aug 21, 2026
…1) (#99)

Three open alerts all concern the same transitive js-yaml 4.x copies, which
Antora nests under three of its packages:

- js-yaml 4.1.1 -> 4.3.1 in @antora/content-aggregator,
  @antora/playbook-builder and @antora/ui-loader
  - #10 high   — quadratic CPU consumption in !!omap resolution
                 (CVE-2026-59870 not backported), needs >= 4.3.1
  - #9  high   — YAML merge-key chains force quadratic CPU, needs >= 4.3.0
  - #8  medium — quadratic-complexity DoS in merge key handling via
                 repeated aliases, needs >= 4.2.0

The direct js-yaml dependency is already 5.3.0 and is not in any vulnerable
range, so a blanket override is wrong here: it would downgrade the safe 5.x
direct dependency to the 4.x legacy line. Two major lines are live at once,
so the pin is applied per parent instead, leaving the root dependency at
5.3.0.

The three Antora packages declare "js-yaml": "~4.1", which cannot reach
4.3.1, and Antora's latest stable release (3.1.15) is already in use — only
3.2.0 pre-releases exist upstream. Overrides are therefore the only route to
the patched version without moving to a pre-release Antora.

Verified under Node 22 (the version CI uses; the local default is 18):
npm ci, npm run antora (exit 0), npm test (17/17 pass), npm run pagefind.
The 29 xref errors in the Antora log are pre-existing content issues on main
(stale "next@ocis:ROOT:" targets) and are non-fatal — no failure_level is
configured in site.yml.

All three alerts are fixable and fixed; none are left without a fix. They
remain open until this lands on the default branch.

Signed-off-by: Thomas Müller <1005065+DeepDiver1975@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant